Security Bulletin
Summary
A security vulnerability exists in the open source library Apache Commons FileUpload that is shipped with, and used by, the IBM Business Process Manager products.
Vulnerability Details
By sending a specially crafted request, an attacker might exploit this vulnerability to cause the application to enter into an infinite loop.
CVE-2014-0050
CVSS Base Score: 5.0
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/90987
CVSS Environmental Score*: Undefined
CVSS Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Affected Products and Versions
IBM Business Process Manager Advanced 7.5.x, 8.0.x, 8.5.x
IBM Business Process Manager Standard 7.5.x, 8.0.x, 8.5.x
IBM Business Process Manager Express 7.5.x, 8.0.x, 8.5.x
IBM Business Process Manager Advanced on z/OS 7.5.x, 8.0.x, 8.5.x
Remediation/Fixes
Use one of the following links to install APAR JR49375 as appropriate for your current version of IBM Business Process Manager:
Workarounds and Mitigations
None
Get Notified about Future Security Bulletins
Important Note
IBM strongly suggests that all System z customers be subscribed to the System z Security Portal to receive the latest critical System z security and integrity service. If you are not subscribed, see the instructions on the System z Security web site. Security and integrity APARs and associated fixes will be posted to this portal. IBM suggests reviewing the CVSS scores and applying all security or integrity fixes as soon as possible to minimize any potential risk.
References
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
Disclaimer
Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.
Product Synonym
BPM
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg21670373